PT-2017-2244 · Gnu+3 · Glibc+3

Publicado

2015-12-09

·

Atualizado

2024-05-16

·

CVE-2014-9984

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions glibc versions prior to 2.20
Description The issue is related to the nscd daemon in the GNU C Library, where it does not correctly compute the size of an internal buffer when processing netgroup requests. This could lead to a crash of the nscd daemon or potentially allow code execution as the user running nscd. The vulnerability may be exploited by a remote attacker to cause a denial of service or to inject code by running the nscd service.
Recommendations For versions prior to 2.20, update to version 2.20 or later to resolve the issue. As a temporary workaround, consider restricting access to the nscd daemon to minimize the risk of exploitation.

Exploit

Correção

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2015-2084
BDU:2017-01438
CVE-2014-9984
SUSE-SU-2018:0076-1
USN-6762-1

Produtos afetados

Alt Linux
Suse
Ubuntu
Glibc